CVE-2026-4438
gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
11th
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
| CWE | CWE-20 |
| Vendor | the gnu c library |
| Product | glibc |
| Published | Mar 20, 2026 |
| Last Updated | Mar 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for the gnu c library glibc
Be the first to know when new medium vulnerabilities affecting the gnu c library glibc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
The GNU C Library / glibc
2.34 โค 2.43
References
Credits
Antonio Maini (0rbitingZer0) - [email protected]